Vulnerability index

Browse CVEs

93 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
I CRITICAL 9.8
CVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au…

No fix yet
Fix from $5,750 2026-08-13
I CRITICAL 9.8
CVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

No fix yet
Fix from $5,750 2026-08-13
Security Verify Access HIGH 8.1
CVE-2026-12359

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $4,900 2026-08-12
Security Verify Access HIGH 7.4
CVE-2026-11923

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $4,900 2026-08-12
Websphere Application Server HIGH 7.3
CVE-2026-10845

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applicatio…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-22
Aspera High Speed Transfer Server For Cloud Pak For Integration CRITICAL 9.1
CVE-2026-7876

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage …

Fix: 1.5.20+
Fix from $2,300 2026-05-27
Security Verify Access CRITICAL 9.8
CVE-2026-4101

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $2,300 2026-04-01
I HIGH 7.8
CVE-2024-27275

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user withou…

Mitigation only
Fix from $1,950 2024-06-15
Ds8900f Firmware CRITICAL 9.8
CVE-2023-46172

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions fo…

Mitigation only
Fix from $2,300 2024-03-07
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2023-38367

IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1,…

Mitigation only
Fix from $1,600 2024-02-29
Watson Iot Platform HIGH 7.5
CVE-2023-38372

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platfo…

Mitigation only
Fix from $1,950 2024-02-29
Spectrum Scale Container Native Storage Access HIGH 7.5
CVE-2022-41738

IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from externa…

Fix: after 5.1.7.0
Fix from $1,950 2024-02-17
Spectrum Scale Container Native Storage Access MEDIUM 6.5
CVE-2022-41737

IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outsi…

Fix: after 5.1.7.0
Fix from $1,600 2024-02-17
Powersc MEDIUM 5.3
CVE-2023-50934

IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a…

Patch available
Fix from $1,600 2024-02-02
Cognos Dashboards On Cloud Pak For Data MEDIUM 6.5
CVE-2023-38735

IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw.…

Patch available
Fix from $1,600 2023-10-22
Urbancode Deploy MEDIUM 6.5
CVE-2023-40376

IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated use…

Fix: after 7.3.2.0
Fix from $1,600 2023-10-04
Cloud Pak For Data HIGH 7.5
CVE-2023-27877

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the …

Patch available
Fix from $1,950 2023-07-19
Robotic Process Automation MEDIUM 5.3
CVE-2023-35901

IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow inv…

Fix: after 23.0.6
Fix from $1,600 2023-07-17
Robotic Process Automation MEDIUM 6.5
CVE-2022-46773

IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential poo…

Fix: 21.0.7.1 / 23.0.1+
Fix from $1,600 2023-03-15
Manage Application MEDIUM 6.5
CVE-2022-46774

IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to …

Mitigation only
Fix from $1,600 2023-03-15
Security Verify Governance MEDIUM 5.3
CVE-2022-35646

IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's acc…

Patch available
Fix from $1,600 2022-12-22
Websphere Automation For Ibm Cloud Pak For Watson Aiops MEDIUM 6.5
CVE-2022-43900

IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbo…

Fix: 1.4.3+
Fix from $1,600 2022-12-01
Powervm Hypervisor CRITICAL 9.8
CVE-2022-34331

After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VE…

Mitigation only
Fix from $2,300 2022-11-11
Maximo Asset Management HIGH 8.1
CVE-2022-40616

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tas…

Mitigation only
Fix from $1,950 2022-09-21
In Band Manageability HIGH 7.2
CVE-2021-0193

Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escala…

Fix: 2.13.0+
Fix from $1,950 2022-05-12
Cognos Controller CRITICAL 9.8
CVE-2020-4879

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth…

Mitigation only
Fix from $2,300 2022-01-21
Spectrum Copy Data Management HIGH 7.5
CVE-2021-39064

IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the S…

Fix: after 2.2.13
Fix from $1,950 2021-12-13
Cloud Pak For Security CRITICAL 9.8
CVE-2021-20578

IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or m…

Patch available
Fix from $2,300 2021-09-30
Infosphere Data Replication CRITICAL 9.8
CVE-2020-4821

IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypa…

Patch available
Fix from $2,300 2021-07-16
Spectrum Lsf HIGH 7.8
CVE-2020-4983

IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitr…

Patch available
Fix from $1,950 2021-01-20